DOP-C02 · Question #242
A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all…
The correct answer is A. Create an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the. To provision new accounts for a multi-environment application with an initial baseline and AWS Control Tower guardrails with least operational overhead, use AWS Control Tower Account Factory Customization (AFC) to define and apply the custom baseline during account creation.
Question
A company needs to adopt a multi-account strategy to deploy its applications and the associated CI/CD infrastructure. The company has created an organization in AWS Organizations that has all features enabled. The company has configured AWS Control Tower and has set up a landing zone. The company needs to use AWS Control Tower controls (guardrails) in all AWS accounts in the organization. The company must create the accounts for a multi-environment application and must ensure that all accounts are configured to an initial baseline. Which solution will meet these requirements with the LEAST operational overhead?
Options
- ACreate an AWS Control Tower Account Factory Customization (AFC) blueprint that uses the
- BUse AWS Control Tower Account Factory to provision a dedicated AWS account for each
- CUse Organizations to provision a multi-environment AWS account and a CI/CD account. In the
- DUse Organizations to provision a dedicated AWS account for each environment, an audit account,
How the community answered
(42 responses)- A81% (34)
- B5% (2)
- C2% (1)
- D12% (5)
Why each option
To provision new accounts for a multi-environment application with an initial baseline and AWS Control Tower guardrails with least operational overhead, use AWS Control Tower Account Factory Customization (AFC) to define and apply the custom baseline during account creation.
AWS Control Tower Account Factory Customization (AFC) allows extending the default Control Tower account baseline with custom configurations through blueprints, ensuring that all newly provisioned accounts for different environments automatically receive both Control Tower guardrails and a company-specific initial baseline with minimal operational overhead.
Using only the AWS Control Tower Account Factory provisions accounts with the default Control Tower baseline but does not include the ability to apply a *custom* initial baseline, thus requiring additional manual steps or separate automation.
Provisioning accounts directly through AWS Organizations bypasses the AWS Control Tower Account Factory, meaning these accounts would not automatically be enrolled in the Control Tower landing zone or receive its guardrails and baseline, leading to higher operational overhead for compliance.
Similar to option C, provisioning accounts directly via AWS Organizations prevents the automatic application of AWS Control Tower guardrails and the baseline, increasing the manual effort needed to ensure compliance and initial configuration.
Concept tested: AWS Control Tower Account Factory Customization for multi-account strategy
Source: https://docs.aws.amazon.com/controltower/latest/userguide/account-factory-customizations.html
Topics
Community Discussion
No community discussion yet for this question.